Windows 10: Windows 10 svchost virus

Discus and support Windows 10 svchost virus in AntiVirus, Firewalls and System Security to solve the problem; Hi. I have recently started having CPU problems. Apparently, it's because of a trojan virus called svchost.exe. Anytime I use an internet browser (any)... Discussion in 'AntiVirus, Firewalls and System Security' started by victor122, Jan 19, 2017.

  1. victor122 Win User

    Windows 10 svchost virus


    Hi. I have recently started having CPU problems. Apparently, it's because of a trojan virus called svchost.exe. Anytime I use an internet browser (any) I get a message from my web protection that it's blocking the virus but my CPU still gets overloaded. I've tried every trojan remover I could find, they did not work. Malwarebytes identifies it as a web virus and blocks every few seconds. How can I remove this virus from my computer?


    Thanks in Advance

    :)
     
    victor122, Jan 19, 2017
    #1

  2. wINDOWS 10 DOES NOT USE THIS TYPE OF FILE? C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup wHY DO i HAVE THIS FILE APPEARING RUNNING ON MY WINDOWS 10 SYSTEM

    wINDOWS 10 DOES NOT USE THIS TYPE OF FILE? C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup wHY DO i HAVE THIS FILE APPEARING RUNNING ON MY WINDOWS 10 SYSTEM

    THE FOLLOWING ALSO APPEAR AND IT HAS CRASHED MY SYSTEM 2 TIMES IS IS A VIRUS?



    Your message is ready to be sent with the following file or link attachments: svcWINDOWS BLOCK THESE POTENTIAL UNSAFE ATTACHEMENTS: host, svchost, svchost, svchost, svchost, svchost, svchost, svchost.exe.mui, svchost.exe.mui, svchost.exe.mui, svchost.exe.mui,
    svchost



    svchost

    svchost

    svchost

    svchost

    svchost

    svchost

    svchost

    svchost.exe.mui

    svchost.exe.mui

    svchost.exe.mui

    svchost.exe.mui

    svchost
     
    albertocarvajal, Jan 19, 2017
    #2
  3. Jsssssssss, Jan 19, 2017
    #3
  4. Samuria Win User

    Windows 10 svchost virus

    Welcome to the forum. The file is a genuine Windows file when run from Windows folder use task manager and find one that's not running from Windows folder kill it quick then delete it you need to have it ready in another window to delete before it restarts it's often random ware are your files OK docs etc
     
    Samuria, Jan 19, 2017
    #4
  5. victor122 Win User
    The thing is that it does operate from the windows folder. From system 32 to be exact.
     
    victor122, Jan 19, 2017
    #5
  6. dalchina New Member
    .. let's go back to that. Do you perhaps mean svchost.exe is using excessive CPU time?

    If so, please post an appropriate screenshot of your task manager. Thanks.
     
    dalchina, Jan 19, 2017
    #6
  7. victor122 Win User
    Windows 10 svchost virus [​IMG]

    Windows 10 svchost virus [​IMG]

    This is what I get while using any browser. The browser starts using more CPU when that message pops up (which happens every few seconds).
     
    victor122, Jan 19, 2017
    #7
  8. dalchina New Member

    Windows 10 svchost virus

    Hi, someone may be able to recognise what's going on if they've seen that, so thanks for the screenshots.

    Meanwhile, you've clearly got quite a bit going on, so try a clean boot, then open a browser and see what happens.

    That's a German IP address - which whois says is for sale.

    Possible references here:
    Qadars Banking Malware Fake Flash Update | EFORENSICS
    Fake Flash update from phishing site delivers Qadars banking malware – BroadAnalysis

    Sounds like you need to scan your system with the appropriate tool, but I'm no expert on that.

    *** This looks possible - see 'Contacted Hosts' which lists yours.
    You could examine the parameters for update.exe as listed here.
    Free Automated Malware Analysis Service - powered by VxStream Sandbox

    Do you have a disk image you can use to restore your PC to a point before this started to occur? I doubt a system restore point would help here.
     
    dalchina, Jan 19, 2017
    #8
  9. victor122,

    Let's try opening the hosts file and see if there is something unusual there.

    Right-click the Windows Start and select: Command Prompt (Admin)

    At the Command Prompt, type the following commands, one at a time, and press ENTER after each::

    cd drivers
    cd etc
    dir


    The contents are shown, and below them, the following appears:
    C:\Windows\System32\drivers\etc>

    At the above, type: notepad hosts

    The Notepad text appears.

    Please copy the results, and provide in your reply.

    (Images are in reversed order!)
     
    cottonball, Jan 20, 2017
    #9
  10. victor122 Win User
    Here is what I got:
    # Copyright (c) 1993-2009 Microsoft Corp.## This is a sample HOSTS file used by Microsoft TCP/IP for Windows.## This file contains the mappings of IP addresses to host names. Each# entry should be kept on an individual line. The IP address should# be placed in the first column followed by the corresponding host name.# The IP address and the host name should be separated by at least one# space.## Additionally, comments (such as these) may be inserted on individual# lines or following the machine name denoted by a '#' symbol.## For example:## 102.54.94.97 rhino.acme.com # source server# 38.25.63.10 x.acme.com # x client host# localhost name resolution is handled within DNS itself.# 127.0.0.1 localhost# ::1 localhost
     
    victor122, Jan 20, 2017
    #10
  11. victor122 Win User
    Maybe this is better

    Windows 10 svchost virus [​IMG]
     
    victor122, Jan 20, 2017
    #11
  12. dalchina New Member
    Whilst you could block that IP address in your hosts file as an expedient, it doesn't deal with the underlying issue. You have some program on your PC which is responsible for that.

    If you find update.exe is present and might be suspicious, you can upload it to Virustotal
    VirusTotal - Free Online Virus, Malware and URL Scanner
    and any positive results might point you to an AV provider that could help.
     
    dalchina, Jan 20, 2017
    #12
  13. Windows 10 svchost virus

    victor122,

    The hosts file is OK.

    Let's do the following:

    Download Zemana AntiMalware:
    Zemana AntiMalware Download
    Save to the Desktop.

    Double-click on the file Zemana.AntiMalware.Setup.exe to install.

    When the program starts you are presented with a Setup screen, click: Next
    Follow the prompts to install.

    Once Zemana AntiMalware starts, click: Scan

    When finished, it displays a list of all the malware found. Click on Next to remove any malicious files from your computer.

    A reboot may be required to remove malware.

    When done, click the Graph icon (far upper right), highlight the applicable log file, and click: Open Report

    Please post the notepad text report for review.
     
    cottonball, Jan 20, 2017
    #13
  14. victor122 Win User
    That didn't help but thanks. The trojan seems to be operating from a different program/file now called tor. Happened after i blocked its IP.

    Windows 10 svchost virus [​IMG]
     
    victor122, Jan 21, 2017
    #14
  15. victor122,

    Please use the Farbar Recovery Scan Tool Download
    Save FRST to your Desktop.

    [Note: You need to run the version compatible with your system: 32 bit or 64 bit]


    Double-click FRST to run it.
    When the tool opens click Yes to the disclaimer.

    Next, press the Scan button.


    When done, the tool makes a log (FRST.txt) on the Desktop.
    The first time the tool is run, it makes another log: (Addition.txt).

    Please provide the results of both reports in your reply. (Attach if you can, if not, then post.)
     
    cottonball, Jan 21, 2017
    #15
Thema:

Windows 10 svchost virus

Loading...
  1. Windows 10 svchost virus - Similar Threads - svchost virus

  2. blocage de svchost

    in Windows 10 Gaming
    blocage de svchost: Bonjour,Depuis un petit moment, j'ai ce message qui apparait "Pour votre protection, votre administrateur n vous autorise pas à accéder au contenu à partir de C;\Windows\system32\dvchost.exe"J'ai beau cliquer sur "Débloquer", cela revient en permanenceJe suis seul...
  3. blocage de svchost

    in Windows 10 Software and Apps
    blocage de svchost: Bonjour,Depuis un petit moment, j'ai ce message qui apparait "Pour votre protection, votre administrateur n vous autorise pas à accéder au contenu à partir de C;\Windows\system32\dvchost.exe"J'ai beau cliquer sur "Débloquer", cela revient en permanenceJe suis seul...
  4. svchost error

    in Windows 10 BSOD Crashes and Debugging
    svchost error: svchost 3720,T,97 SRUJet: A request to write to the file "C:\WINDOWS\system32\SRU\SRUDB.dat" at offset 0 0x0000000000000000 for 4096 0x00001000 bytes succeeded, but took an abnormally long time 21 seconds to be serviced by the OS. This problem is likely due to faulty...
  5. svchost error

    in Windows 10 Gaming
    svchost error: svchost 3720,T,97 SRUJet: A request to write to the file "C:\WINDOWS\system32\SRU\SRUDB.dat" at offset 0 0x0000000000000000 for 4096 0x00001000 bytes succeeded, but took an abnormally long time 21 seconds to be serviced by the OS. This problem is likely due to faulty...
  6. svchost error

    in Windows 10 Software and Apps
    svchost error: svchost 3720,T,97 SRUJet: A request to write to the file "C:\WINDOWS\system32\SRU\SRUDB.dat" at offset 0 0x0000000000000000 for 4096 0x00001000 bytes succeeded, but took an abnormally long time 21 seconds to be serviced by the OS. This problem is likely due to faulty...
  7. Windows Windows successfully diagnosed a low virtual memory condition. Svchost using almost...

    in Windows 10 Gaming
    Windows Windows successfully diagnosed a low virtual memory condition. Svchost using almost...: HelloI have around 27 PCs on a site that intermittently experience software crashes a few times a week each. My software is a unity standalone build. After further investigation, it seems that many of these crashes are caused by 'System out of memory' issues. Looking at the...
  8. Windows Windows successfully diagnosed a low virtual memory condition. Svchost using almost...

    in Windows 10 Software and Apps
    Windows Windows successfully diagnosed a low virtual memory condition. Svchost using almost...: HelloI have around 27 PCs on a site that intermittently experience software crashes a few times a week each. My software is a unity standalone build. After further investigation, it seems that many of these crashes are caused by 'System out of memory' issues. Looking at the...
  9. why does svchost have my mic.

    in Windows 10 Software and Apps
    why does svchost have my mic.: I have tried the many ways to either remove or at least find out what pgm has the mic. I am running windows 10 pro. most of the ways discribed in the previous answers do not even aply to the current win10 pro os. the mic is dead, cant even wake it up in control panel....
  10. Svchost virus?

    in AntiVirus, Firewalls and System Security
    Svchost virus?: Hi i just discovered the svchost trojan and have a few questions is it a rootkit virus and will completely wiping my hard drive destroy it....